-Caveat Lector-

Borland Interbase backdoor exposed
By: Kevin Poulsen
Posted: 12/01/2001 at 05:45 GMT

 A back door password has been hidden in Borland/Inprise's
popular Interbase database software for at least seven years,
potentially exposing tens of thousands of private databases at
corporations and government agencies to unauthorized access and
manipulation over the Internet, experts say.

 Analysts report that the account name 'politically' with the
password 'correct' unlocks access to Interbase versions 4.0, 5.0
and 6.0 over the Net, and on any platform. Moreover, because
Interbase has the ability to execute user-defined functions, the
back door can be used to inject malicious code into a system,
which could give an attacker administrative access to the
computer itself, according to a Wednesday advisory from Carnegie
Mellon University's Computer Emergency Response Team (CERT).

 "The back door account password cannot be changed using normal
operational commands, nor can the account be deleted from
existing vulnerable server," the CERT warning states.

 Jim Starkey, architect of the original, 1985 version of Interbase --
which did not contain a back door -- says hackers have already
begun scanning the Internet for services on TCP port 3050, the
default port for Interbase servers.

 Balance of the story:
   http://www.theregister.co.uk/content/6/16023.html

<A HREF="http://www.ctrl.org/">www.ctrl.org</A>
DECLARATION & DISCLAIMER
==========
CTRL is a discussion & informational exchange list. Proselytizing propagandic
screeds are unwelcomed. Substance—not soap-boxing—please!  These are
sordid matters and 'conspiracy theory'—with its many half-truths, mis-
directions and outright frauds—is used politically by different groups with
major and minor effects spread throughout the spectrum of time and thought.
That being said, CTRLgives no endorsement to the validity of posts, and
always suggests to readers; be wary of what you read. CTRL gives no
credence to Holocaust denial and nazi's need not apply.

Let us please be civil and as always, Caveat Lector.
========================================================================
Archives Available at:
http://peach.ease.lsoft.com/archives/ctrl.html
 <A HREF="http://peach.ease.lsoft.com/archives/ctrl.html">Archives of
[EMAIL PROTECTED]</A>

http:[EMAIL PROTECTED]/
 <A HREF="http:[EMAIL PROTECTED]/">ctrl</A>
========================================================================
To subscribe to Conspiracy Theory Research List[CTRL] send email:
SUBSCRIBE CTRL [to:] [EMAIL PROTECTED]

To UNsubscribe to Conspiracy Theory Research List[CTRL] send email:
SIGNOFF CTRL [to:] [EMAIL PROTECTED]

Om

Reply via email to